<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Fortinet Security Blog &#187; conference</title>
	<atom:link href="http://blog.fortinet.com/tag/conference/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.fortinet.com</link>
	<description>Real Time Network Protection</description>
	<lastBuildDate>Fri, 27 Jan 2012 11:59:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
	<!-- podcast_generator="podPress/8.8" -->
		<copyright>&#xA9;Fortinet Product Marketing </copyright>
		<managingEditor>rpopko@fortinet.com (Fortinet Product Marketing)</managingEditor>
		<webMaster>rpopko@fortinet.com(Fortinet Product Marketing)</webMaster>
		<category>Fortinet Product Information</category>
		<ttl>1440</ttl>
		<itunes:keywords>forti-gate, anti-spam, anti-virus, fortigate</itunes:keywords>
		<itunes:subtitle>The latest news and information about Fortinet products and services for Real Time Network Protection.</itunes:subtitle>
		<itunes:summary>Fortinet is a leading provider of Unified Threat Management (UTM) network security solutions for enterprise and service provider environments. The Fortinet FortiCast delivers news, information, and tutorials about products, services, and industry trends. Fortinet's FortiGate product line and FortiGuard security subscription services provide an array of integrated network security functions including antivirus, firewall, virtual private networking, intrusion prevention (IPS), web filtering, antispam and traffic optimization. </itunes:summary>
		<itunes:author>Fortinet Product Marketing</itunes:author>
		<itunes:category text="Technology"/>
<itunes:category text="Technology">
  <itunes:category text="Tech News"/>
</itunes:category>
		<itunes:owner>
			<itunes:name>Fortinet Product Marketing</itunes:name>
			<itunes:email>rpopko@fortinet.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-300x300.jpg" />
		<image>
			<url>http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-144x144.jpg</url>
			<title>Fortinet Security Blog</title>
			<link>http://blog.fortinet.com</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>[FortiChallenge 2k11] Results</title>
		<link>http://blog.fortinet.com/fortichallenge-2k11-results/</link>
		<comments>http://blog.fortinet.com/fortichallenge-2k11-results/#comments</comments>
		<pubDate>Tue, 15 Nov 2011 14:45:15 +0000</pubDate>
		<dc:creator>Alexandre Aumoine</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[hacking challenge]]></category>
		<category><![CDATA[insomni’hack]]></category>
		<category><![CDATA[reverse engineering]]></category>
		<category><![CDATA[reversing]]></category>
		<category><![CDATA[symbian]]></category>
		<category><![CDATA[symbianos]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=3628</guid>
		<description><![CDATA[Thank you to everyone who tried to solve our FortiChallenge 2k11! We&#8217;ve had way more participants than expected, and two winners : Shirley Chen Nagy Ferenc László Shirley and Nagy found the secret sentence, without even using the hints. A special mention for another participant (StalkR) who tried to solve it in the wake of [...]]]></description>
			<content:encoded><![CDATA[<p>Thank you to everyone who tried to solve our FortiChallenge 2k11!</p>
<p>We&#8217;ve had way more participants than expected, and two winners :</p>
<ol>
<li>Shirley Chen</li>
<li>Nagy Ferenc László</li>
</ol>
<p>Shirley and Nagy found the secret sentence, without even using the hints.</p>
<p>A special mention for another participant (<a href="http://blog.stalkr.net">StalkR</a>) who tried to solve it in the wake of Insomni’Hack 2011, and managed to reach the md5 collision step.</p>
<p>Stay tuned for the official solution!</p>
<p>&#8211; the Reverse naM</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/fortichallenge-2k11-results/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[FortiChallenge 2k11] Hint #2</title>
		<link>http://blog.fortinet.com/fortichallenge-2k11-hint-2/</link>
		<comments>http://blog.fortinet.com/fortichallenge-2k11-hint-2/#comments</comments>
		<pubDate>Thu, 03 Nov 2011 13:40:05 +0000</pubDate>
		<dc:creator>Alexandre Aumoine</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[hacking challenge]]></category>
		<category><![CDATA[insomni’hack]]></category>
		<category><![CDATA[reverse engineering]]></category>
		<category><![CDATA[reversing]]></category>
		<category><![CDATA[symbian]]></category>
		<category><![CDATA[symbianos]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=3590</guid>
		<description><![CDATA[Any progress on our FortiChallenge 2k11? After the first clue, here is the second. Just a reminder that the first hint is meant to help you to find the good way with hashes. Don&#8217;t miss the modification, Crypto Girl hates MD5 for this reason ! By the way, challenge&#8217;s submission deadline is extended to Nov [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-3491" src="http://blog.fortinet.com/wp-content/uploads/2011/10/sherlock-holmes-silouette-with-text-md.png" alt="" width="179" height="167" />Any progress on our <a href="http://blog.fortinet.com/fortihallenge-2k11/">FortiChallenge 2k11</a>? After the <a href="http://blog.fortinet.com/fortichallenge-2k11-hint-1/">first clue</a>, here is the second.</p>
<p>Just a reminder that the first hint is meant to help you to find the good way with hashes.</p>
<p>Don&#8217;t miss the <strong>modification</strong>, Crypto Girl hates MD5 for this reason !</p>
<p>By the way, challenge&#8217;s submission deadline is extended to <strong>Nov 13th, 2011</strong>.</p>
<p>&#8211;</p>
<p>The Reverse naM</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/fortichallenge-2k11-hint-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>[FortiChallenge 2k11] Hint #1</title>
		<link>http://blog.fortinet.com/fortichallenge-2k11-hint-1/</link>
		<comments>http://blog.fortinet.com/fortichallenge-2k11-hint-1/#comments</comments>
		<pubDate>Fri, 21 Oct 2011 09:44:31 +0000</pubDate>
		<dc:creator>Alexandre Aumoine</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[hacking challenge]]></category>
		<category><![CDATA[insomni’hack]]></category>
		<category><![CDATA[reverse engineering]]></category>
		<category><![CDATA[reversing]]></category>
		<category><![CDATA[symbian]]></category>
		<category><![CDATA[symbianos]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=3507</guid>
		<description><![CDATA[Stuck on our FortiChallenge 2k11? Here&#8217;s a first hint! Translations: La fin est encore loin surtout quand on est sur le mauvais chemin ! Wrong track, go back! La fin est proche, l&#8217;anneau est inclus. Dawn is close, search for the ring. Mon precieux My precious Hint: -6D01BAE018694CDB446DC7EADBA08BE497A8CBE78BCFE91478AB120B4400E357 -ad23ebc59b720eac0979ead3176de3331ddaa1356466ecc8e8c9fb82f62a6dca -BCA85F09D8D174844C5D5B80095E6EF595181AAB0CABA9144324418B9F291645 -3EE90318AA2881118B8C09A777D52129E61760CCAE1EF679C744A25E9EB50789 -5868049FE51A60811D2C75C3B8896B956EE42114C568DE47531E436CEA2E0F77 – the Reverse [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-3491" src="http://blog.fortinet.com/wp-content/uploads/2011/10/sherlock-holmes-silouette-with-text-md.png" alt="" width="179" height="167" />Stuck on our <a href="http://blog.fortinet.com/fortihallenge-2k11/">FortiChallenge 2k11</a>? Here&#8217;s a first hint!</p>
<p><strong>Translations:</strong></p>
<p>La fin est encore loin surtout quand on est sur le mauvais chemin !<br /> Wrong track, go back!</p>
<p>La fin est proche, l&#8217;anneau est inclus.<br /> Dawn is close, search for the ring.</p>
<p>Mon precieux<br /> My precious</p>
<p><strong>Hint:</strong></p>
<pre>-6D01BAE018694CDB446DC7EADBA08BE497A8CBE78BCFE91478AB120B4400E357
-ad23ebc59b720eac0979ead3176de3331ddaa1356466ecc8e8c9fb82f62a6dca
-BCA85F09D8D174844C5D5B80095E6EF595181AAB0CABA9144324418B9F291645
-3EE90318AA2881118B8C09A777D52129E61760CCAE1EF679C744A25E9EB50789
-5868049FE51A60811D2C75C3B8896B956EE42114C568DE47531E436CEA2E0F77</pre>
<p>– the Reverse naM</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/fortichallenge-2k11-hint-1/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>FortiChallenge 2k11</title>
		<link>http://blog.fortinet.com/fortihallenge-2k11/</link>
		<comments>http://blog.fortinet.com/fortihallenge-2k11/#comments</comments>
		<pubDate>Mon, 17 Oct 2011 13:33:37 +0000</pubDate>
		<dc:creator>Alexandre Aumoine</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[hacking challenge]]></category>
		<category><![CDATA[insomni’hack]]></category>
		<category><![CDATA[reverse engineering]]></category>
		<category><![CDATA[reversing]]></category>
		<category><![CDATA[symbian]]></category>
		<category><![CDATA[symbianos]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=2789</guid>
		<description><![CDATA[Hello all, At Insomni&#8217;Hack 2011, we created a challenge dedicated to static reversing of Symbian executables (using SDK S60 Ed3 FP1). Sadly, nobody found the full solution, so we finally decided to put it online for you to try, until November 1st, 2011. We will then post the winner&#8217;s solution on this blog, along with [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-3491" src="http://blog.fortinet.com/wp-content/uploads/2011/10/sherlock-holmes-silouette-with-text-md.png" alt="" width="179" height="167" />Hello all,</p>
<p>At <a href="https://blog.fortinet.com/insomnihack-2011/">Insomni&#8217;Hack 2011</a>, we created a challenge dedicated to static reversing of Symbian executables (using SDK S60 Ed3 FP1). Sadly, nobody found the full solution, so we finally decided to put it online for you to try, <strong>until November 1st, 2011</strong>. We will then post the winner&#8217;s solution on this blog, along with the &#8216;official&#8217; solution. To help you out &#8211; if needed &#8211; this post will be updated with a hint in a few days.</p>
<p>Challenge prize? the winner (first good solution) receives &#8230; fame and glory :)) i.e. nothing besides marketing goodies, if desired :D</p>
<p>Challenge steps:</p>
<ul>
<li>retrieve the archive <a href="http://dl.free.fr/iglplOhDa">here</a></li>
</ul>
<pre>sha256 =&gt; B74D50104499C35EE9544A77A0DD491646991CD2B3780A7571377152A5F65BD0
P@55 =&gt; *Dneige</pre>
<p>No  username. 7z archive contains an IDA disassembly, an executable, some snapshots and a readme</p>
<ul>
<li>find the secret sentence</li>
</ul>
<ul>
<li>send us an e-mail at FORTIChallenge@fortinet.com with the secret sentence and explain the solution you used.</li>
</ul>
<p>That&#8217;s all for today, happy RE !</p>
<p>&#8211; the Reverse naM</p>
<p><strong>Update Oct 21 2011:</strong> <a href="http://blog.fortinet.com/fortichallenge-2k11-hint-1/">Hint #1</a></p>
<p><strong>Update Nov 3 2011: </strong><a title="Hint #2" href="http://blog.fortinet.com/fortichallenge-2k11-hint-2/">Hint #2</a><strong><br />
</strong></p>
<p><strong>Update Nov 15 2011: </strong><a title="Results" href="http://blog.fortinet.com/fortichallenge-2k11-results/">Results</a><strong><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/fortihallenge-2k11/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>Insomni&#8217;Hack 2011</title>
		<link>http://blog.fortinet.com/insomnihack-2011/</link>
		<comments>http://blog.fortinet.com/insomnihack-2011/#comments</comments>
		<pubDate>Fri, 18 Mar 2011 15:52:36 +0000</pubDate>
		<dc:creator>Alexandre Aumoine</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[hacking challenge]]></category>
		<category><![CDATA[insomni'hack]]></category>
		<category><![CDATA[reverse engineering]]></category>
		<category><![CDATA[reversing]]></category>
		<category><![CDATA[symbian]]></category>
		<category><![CDATA[symbianos]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=2653</guid>
		<description><![CDATA[Last week we attended Insomni&#8217;Hack 2011, where our Crypto Girl (Axelle Apvrille) presented  on mobile phone threats. Debriefing of the conference  may be found here and there. Both blog authors highlighted the main goal of Axelle&#8217;s talk, which was to raise awareness about existing threats on smartphones. Mobile phones had already been targeted for a [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-2660" href="http://blog.fortinet.com/insomnihack-2011/4_readme/"><img class="alignleft" style="margin: 6px 8px;" src="http://blog.fortinet.com/wp-content/uploads/2011/03/4_Readme.jpg" alt="" width="240" height="320" /></a>Last week we attended <a href="http://www.scrt.ch/insomnihack/2011/presentation" target="_blank">Insomni&#8217;Hack 2011</a>, where our Crypto Girl (Axelle Apvrille) presented  on mobile phone threats.<br />
Debriefing of the conference  may be found <a href="http://bruno.kerouanton.net/blog/2011/03/05/insomnihack-2011-cest-fini/" target="_blank">here</a> and <a href="http://www.segmentationfault.fr/securite-informatique/insomnihack-2011/" target="_blank">there</a>. Both blog authors highlighted the main goal of Axelle&#8217;s talk, which was to raise awareness about existing threats on smartphones.</p>
<p>Mobile phones had already been targeted for a long time (by application sending sms for instance) but since recently (approximately one year) it has been hit by more advanced attacks &#8211; probably with the help of cybercriminal organizations.</p>
<p>Their goal is to earn money quickly and for this purpose, they develop a botnet-like infrastructure much like in the PC world, the goal being to dispose of an army of zombie phones. The examples of this trend are Android/Geinimi and <a href="https://blog.fortinet.com/android-droiddream-uses-two-vulnerabilities/" target="_blank">Android/DroidDream</a> with their standard features:</p>
<ul>
<li>Trojan</li>
<li>C&amp;C</li>
<li>Silent install</li>
<li>&#8230;</li>
</ul>
<p>With such botnets at disposal, cybercriminals can potentially sell &#8216;underground&#8217; services like sms spam, silent application install (pay-per-install), &#8216;click jacking&#8217;, Black SEO and  other &#8216;non ethical&#8217; lucrative business. Of course `Extra charges` will end up on the infected user&#8217;s monthly bill :( .</p>
<p>On my side I designed and implemented a challenge for the competition. It is based on Symbian OS and the main goal is to practice some &#8216;static reversing&#8217; on the sample.</p>
<p>This will allow you to extract a secret sentence.<br />
At this time (waiting confirmation from SCRT.CH), it seems that nobody has solved the challenge during the event (6PM to 1AM).</p>
<p>From my point of view I think this is due to several factors:</p>
<ol>
<li> It is difficult to understand the SIS file format or ARM instructions without some help (internet not available during the challenge to the staff&#8217;s great displeasure)</li>
<li>No specific tools was provided like a sis file explorer or extractor (my  fault)</li>
<li>I am a &#8216;n00b&#8217; of challenge writing, so probably I used to much stages/steps for the time that the challengers had</li>
<li>Already more than 30 challenges available</li>
</ol>
<p>Everything will be (un)confirmed by the feedback of competitors (don&#8217;t hesitate to post &#8216;useful&#8217; comments on it).</p>
<p>Some solutions of challenges from <a href="http://crypto.junod.info/2011/03/07/insomnihack-2011-souvenirs-souvenirs/" target="_blank">Junod itself</a> and other competitors (severals challenges <a href="http://www.linux-backtrack.com/2011/03/insomni’hack-2011/" target="_blank">here</a>, the <a href="http://blog.stalkr.net/2011/03/insomnihack-gpgpu-reversing.html" target="_blank">GPGPU reverse</a> and the <a href="http://blog.nibbles.fr/2372" target="_blank">reverse 2</a>)</p>
<p>&#8211; the Reverse naM</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/insomnihack-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ShmooCon 2011 Debriefing</title>
		<link>http://blog.fortinet.com/shmoocon-2011-debriefing/</link>
		<comments>http://blog.fortinet.com/shmoocon-2011-debriefing/#comments</comments>
		<pubDate>Wed, 09 Feb 2011 17:23:09 +0000</pubDate>
		<dc:creator>Axelle</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[hashcat]]></category>
		<category><![CDATA[law]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[statistics]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=2287</guid>
		<description><![CDATA[I got back from ShmooCon 2011, in Washington D.C., and would like to share with you a few insights. First, just like in BlackHat DC 2011, this year&#8217;s conference had several talks on smart phones. Good news! I was however slightly surprised they all concerned Android (apart from mine, on Symbian). It is true Android [...]]]></description>
			<content:encoded><![CDATA[<p>I got back from <a href="http://www.shmoocon.org/">ShmooCon</a> 2011, in Washington D.C., and would like to share with you a few insights.</p>
<p>First, just like in BlackHat DC 2011, this year&#8217;s conference had several talks on smart phones. Good news! I was however slightly surprised they all concerned Android (apart from mine, on Symbian). It is true Android platforms are predominant in hacker communities. I feel it is nonetheless important to remind the latest statistics on the matter:</p>
<ul>
<li>In the U.S., Android phones come <em>third</em> (19%) after BlackBerry (31%) and iPhones (28%) (source: <a href="http://blog.nielsen.com/nielsenwire/online_mobile/android-most-popular-operating-system-in-u-s-among-recent-smartphone-buyers/">Nielsen Wire</a>)</li>
<li>In France/Italy/Germany/Spain/UK, Android phones (6%) are still <em>way behind</em> Symbian (54%), iPhones (19%), Windows Mobile (11%), RIM (8%) (source: <a href="http://metagrafic.es/wp-content/uploads/SMARTPHONES2.png">ComScore</a>)</li>
<li>In Asia, I had more difficulties finding statistics, but it looks like Android comes <em>second</em> (20%) in China, behind Symbian (50%). (ref. <a href="http://www.east-west-connect.com/china-smartphones/2010-2011-china-smartphone-market-overview">ZOL</a>)</li>
</ul>
<p>I believe Symbian is often disregarded because of its decreasing market sales. But quarterly <em>sales</em> are different from <em>owned</em> devices (we don&#8217;t buy a new phone every three months, do we? ) and, also, device&#8217;s distribution is quite different from one country to another.</p>
<p>Nevertheless, the talks on Android were very interesting (and I would sure love to get my hands on a new Gingerbread Android phone). I particularly appreciated <a href="http://www.shmoocon.org/schedule#androidemu">Scott Dunlop</a>&#8216;s talk and live demo. I am used to decompiling Android samples with dex2jar so as to get Java output, but he had me convinced to try and use smali/baksmali tools and loose less reverse engineering information during the process.</p>
<p>The conference also highlighted password cracking issues, with a keynote from <a href="http://www.shmoocon.org/schedule#analytic">Mudge</a> and the <a href="http://www.shmoocon.org/schedule#past">final panel</a>. The problem is far from new, but it is interesting to have up-to-date feedback from hackers who won the <a href="http://contest.korelogic.com/">Defcon password cracking contest in 2010</a>. They concluded that password policies were mostly <em>counter-productive</em>, and that actually <em>writing down passwords</em> isn&#8217;t that bad. Come to think about it, I happen to agree (excepted if you work for a military-grade employer).</p>
<p>Finally, I enjoyed very much the legal-oriented talks of <a href="http://www.youtube.com/watch?v=JHLebJ6BYdU">Tara Whalen</a> (Office of the Privacy Commissioner of Canada) and <a href="http://www.shmoocon.org/schedule#searchandseizure">Marcia Hofmann</a> (Attorney at EFF). Such talks show us computer security from another angle and I believe this is always profitable. Tara Whalen covered the case of Google cars inadvertently collecting packets from open Wifi networks. Marcia Hoffman explained in which circumstances the US government is allowed to seize and search computers of its citizens. In both cases, Google case and computer seizures, it is a bit frightening to see there is an enormous gap between the way government deal with computers and what hackers might actually do (for good or evil).</p>
<p>&#8211; the Crypto Girl</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/shmoocon-2011-debriefing/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Shmoocon 2011 talk: Defeating mTANs for Profit</title>
		<link>http://blog.fortinet.com/shmoocon-2011-talk-defeating-mtans-for-profit/</link>
		<comments>http://blog.fortinet.com/shmoocon-2011-talk-defeating-mtans-for-profit/#comments</comments>
		<pubDate>Thu, 27 Jan 2011 15:40:07 +0000</pubDate>
		<dc:creator>GLovet</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[axelle]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[crypto girl]]></category>
		<category><![CDATA[mobile malware]]></category>
		<category><![CDATA[mobile threat]]></category>
		<category><![CDATA[mobile virus]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[Zeus]]></category>
		<category><![CDATA[zeus in the mobile]]></category>
		<category><![CDATA[zitmo]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=2275</guid>
		<description><![CDATA[Tomorrow starts the quite famous &#8211; and ever sold-out &#8211; security conference Shmoocon, held in Washington DC until Sunday. The keynote this year will be filled by Peiter Mudge Zatko, inventor of L0phtcrack and early pioneer of buffer overflows. Among the talks filling the tri-tracks program (Build it / Break it / Bring it on), [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-2276" href="http://blog.fortinet.com/shmoocon-2011-talk-defeating-mtans-for-profit/shmoo/"><img class="alignleft size-full wp-image-2276" style="margin: 6px 8px;" title="Shmoo" src="http://blog.fortinet.com/wp-content/uploads/2011/01/Shmoo.png" alt="" width="189" height="150" /></a>Tomorrow starts the quite famous &#8211; and ever sold-out &#8211; security conference <a href="http://www.shmoocon.org/">Shmoocon</a>, held in Washington DC until Sunday. The keynote this year will be filled by Peiter Mudge Zatko, inventor of L0phtcrack and early pioneer of buffer overflows.</p>
<p>Among the talks filling the tri-tracks program (Build it / Break it / Bring it on), we&#8217;re glad to find our Crypto Girl, Axelle, who will present a paper she co-wrote with Kyle Yang (another regular poster on this blog) on the infamous mobile phone malware <a href="http://blog.fortinet.com/zeus-in-the-mobile-zitmo-online-bankings-two-factor-authentication-defeated/">Zitmo</a>, that we discovered (simultaneously with Spanish company S21sec) and named last September.</p>
<p>Zitmo stands for &#8220;ZeuS in the Mobile&#8221;; this offspring of the gang behind the infamous banking credential theft kit named &#8220;ZeuS&#8221; has the interesting peculiarity of attacking so-called &#8220;mTAN&#8221; (<strong>mobile Transaction Authentication Number</strong>), which are sent as SMS messages by many banks to serve as a second authentication factor, when customers want to initiate a financial transaction online.</p>
<p>Axelle will elaborate on the details during the preso, so if you&#8217;re around, make sure you attend!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/shmoocon-2011-talk-defeating-mtans-for-profit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Papers of VB2009</title>
		<link>http://blog.fortinet.com/papers-of-vb2009/</link>
		<comments>http://blog.fortinet.com/papers-of-vb2009/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 18:03:14 +0000</pubDate>
		<dc:creator>DMaciejak</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[paper]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[threat level]]></category>
		<category><![CDATA[virus bulletin]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=684</guid>
		<description><![CDATA[The papers Bryan, Guillaume and I presented at Virus Bulletin 2009 have been available on the FortiguardCenter since yesterday: &#8216;I am not a numero!&#8217;: assessing global security threat levels &#8211; Bryan Lu Fighting cybercrime: technical, juridical, and ethical challenges &#8211; Guillaume Lovet Botnet-powered SQL injection attacks: a deeper look within &#8211; David Maciejak &#38; Guillaume [...]]]></description>
			<content:encoded><![CDATA[<p>The papers Bryan, Guillaume and I presented at Virus Bulletin 2009 have been available on the FortiguardCenter since yesterday:</p>
<p><a id="fwgd" title="'I am not a numero!': assessing global security threat levels" href="http://www.fortiguard.com/papers/VB2009_I_am_Not_a_Numero_-_Assessing_Global_Security_Threat_Levels.pdf">&#8216;I am not a numero!&#8217;: assessing global security threat levels</a> &#8211; Bryan Lu</p>
<p><a id="hy:2" title="Fighting cybercrime: technical, juridical, and ethical challenges" href="http://www.fortiguard.com/papers/VB2009_Fighting_Cybercrime_-_Technical,Juridical_and_Ethical_Challenges.pdf">Fighting cybercrime: technical, juridical, and ethical challenges</a> &#8211; Guillaume Lovet</p>
<p><a id="xo4k" title="Botnet-powered SQL injection attacks: a deeper look within" href="http://www.fortiguard.com/papers/VB2009_Botnet-Powered_SQL_Injection_Attacks_-_A_Deeper_Look_Within.pdf">Botnet-powered SQL injection attacks: a deeper look within</a> &#8211; David Maciejak &amp; Guillaume Lovet</p>
<p>It&#8217;s the 4th year in a row that Fortinet has had at least one paper in the line-up, but the first time we hit a count of three presentations.</p>
<p>The conference was held last month in Geneva, Switzerland, and was quite exciting (see program <a id="lajo" title="here" href="http://www.virusbtn.com/conference/vb2009/programme">here</a>). Despite the economic situation, the number of attendants hit a record high this year &#8211; which was perceptible during the keynote presentation, but less so afterwards. It seems as if over time people are considering the conference more as a social and professional networking event than a presentation-driven one.</p>
<p>We did follow some presentations in the corporate and technical tracks, the latter slightly more crowded. There were some nice discussions around current topics such as <a id="o9vm" title="cloud computing" href="http://www.virusbtn.com/conference/vb2009/abstracts/RaduRagragio.xml">cloud computing</a> (Marian Radu and Hilda Larina Ragragio from <em>Microsoft</em>) or <a id="e16s" title="malware sandboxing" href="http://www.virusbtn.com/conference/vb2009/abstracts/Mandl.xml">malware sandboxing</a> (Thomas Mandl <em> Secure Business Austria/IKARUS Security Software, </em>Florian Nentwich <em> IKARUS Security Software</em>, Ulrich Bayer and Engin Kirda from <em>Vienna University of Technology/Institute Eurecom</em>), as well as more traditional <a id="sezm" title="static analysis" href="http://www.virusbtn.com/conference/vb2009/abstracts/DimakilingSengWu.xml">static analysis</a> (Elda Dimakiling,  Francis Allan Tan Seng and Scott Wu from  Microsoft) and <a id="ysws" title="botnet history" href="http://www.virusbtn.com/conference/vb2009/abstracts/LastMinute6.xml">botnet history</a> (<em>Erik Wu and Gunter Ollmann, Damballa</em>). I got particularly interested by the in-depth looks at some threats like <a id="g00r" title="Koobface" href="http://www.virusbtn.com/conference/vb2009/abstracts/LastMinute2.xml">Koobface</a> (Ryan Flores, Joey Costoya and Jonell Baltazar from Trend Micro) or vulnerabilities like MS08-067. Guillaume also shared a good presentation on poorly-known aspects of <a id="fqz3" title="fighting cyber-crime" href="http://www.virusbtn.com/conference/vb2009/abstracts/Lovet.xml">fighting cyber-crime</a>. Threats leveraging popular Internet web sites also had the honor of multiple presentations this year (especially <a id="kak1" title="Twitter" href="http://www.virusbtn.com/conference/vb2009/abstracts/LastMinute3.xml">Twitter</a> and <a id="ggpa" title="Facebook" href="http://www.virusbtn.com/conference/vb2009/abstracts/LastMinute2.xml">Facebook</a>).</p>
<p>In the upcoming events, I would love to see more discussion around mobile security. Besides the <a id="dlct" title="&quot;iPhone v3 malware vector&quot;" href="http://www.virusbtn.com/conference/vb2009/abstracts/LastMinute1.xml">&#8220;iPhone v3 malware vector&#8221;</a> presentation (Marius van Oers from McAfee), the only other one was &#8220;Mobile malware/security: iPhone in the enterprise,&#8221; but unfortunately, it was canceled. Nonetheless, this year&#8217;s  vintage of the iconic conference of the AV industry was good, and as always a perfect occasion to put faces on various names (and beers into various faces). I hope the 2010 one will be just as good, so&#8230; see you in Vancouver ?</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/papers-of-vb2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

